{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-301-do-not-count-ios-open-network-timeline-entries-as-every-wi-fi-reconnection/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-301-do-not-count-ios-open-network-timeline-entries-as-every-wi-fi-reconnection/",
        "slug": "dse-20260909-301-do-not-count-ios-open-network-timeline-entries-as-every-wi-fi-reconnection",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-301-do-not-count-ios-open-network-timeline-entries-as-every-wi-fi-reconnection/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-301-do-not-count-ios-open-network-timeline-entries-as-every-wi-fi-reconnection.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-301-do-not-count-ios-open-network-timeline-entries-as-every-wi-fi-reconnection/"
        },
        "title": "Do not count iOS open-network timeline entries as every Wi-Fi reconnection",
        "summary": "Why can repeated open-Wi-Fi connections produce few Defender timeline events and no new alerts?",
        "format": {
            "slug": "briefing",
            "name": "Briefing"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:26:55+00:00",
        "modified_at": "2026-09-10T01:40:02+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 247,
        "potentially_affected": "Defender for Endpoint on iOS using the open-network event experience introduced with the May 2025 app update, excluding GCC's retained alert behavior.",
        "dse_recommendation": "Interpret the mobile timeline as the documented summarized event signal, not a complete count of network joins.",
        "primary_source": {
            "name": "Configure Microsoft Defender for Endpoint on iOS features - Microsoft Defender for Endpoint | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/defender-endpoint/ios-configure-features",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>With the documented May 2025 iOS app update, Defender open-wireless-network activity moves from alerts to device-timeline events. Repeated connections within a 24-hour period produce only one connection event and one disconnection event. User-trusted open networks are included. The change requires the corresponding app update and does not apply to GCC customers, who retain the previous alert experience. <a href=\"https://learn.microsoft.com/en-us/defender-endpoint/ios-configure-features\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Establish the tenant cloud and installed application version before explaining a quiet alert queue or a small event count. Do not assume that a different device&#8217;s experience proves which behavior applies to the device under investigation.</p>\n<h2>DSE recommendation</h2>\n<p>Interpret the mobile timeline as the documented summarized event signal, not a complete count of network joins. Ask the security operations owner to update searches and help-desk explanations that still expect a new alert for every connection. If the investigation needs connection frequency, identify an authorized evidence source appropriate to that requirement rather than calculating it from these summarized entries. Keep trusted-network status separate from whether an event can appear.</p>\n<h2>Verification</h2>\n<p>On a permitted test device, record the app version and cloud, then compare the observed timeline and alert behavior with the applicable documented path. Preserve the time range and device identity when examining repeated activity. State the observation narrowly: an event establishes the reported activity, but the documented one-per-type limit does not support a total reconnection count. Investigate missing expected evidence without inventing unobserved joins.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/defender-endpoint/ios-configure-features\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Defender for Endpoint iOS features</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nWith the documented May 2025 iOS app update, Defender open-wireless-network activity moves from alerts to device-timeline events. Repeated connections within a 24-hour period produce only one connection event and one disconnection event. User-trusted open networks are included. The change requires the corresponding app update and does not apply to GCC customers, who retain the previous alert experience. Microsoft Learn.\nApplicability\nEstablish the tenant cloud and installed application version before explaining a quiet alert queue or a small event count. Do not assume that a different device’s experience proves which behavior applies to the device under investigation.\nDSE recommendation\nInterpret the mobile timeline as the documented summarized event signal, not a complete count of network joins. Ask the security operations owner to update searches and help-desk explanations that still expect a new alert for every connection. If the investigation needs connection frequency, identify an authorized evidence source appropriate to that requirement rather than calculating it from these summarized entries. Keep trusted-network status separate from whether an event can appear.\nVerification\nOn a permitted test device, record the app version and cloud, then compare the observed timeline and alert behavior with the applicable documented path. Preserve the time range and device identity when examining repeated activity. State the observation narrowly: an event establishes the reported activity, but the documented one-per-type limit does not support a total reconnection count. Investigate missing expected evidence without inventing unobserved joins.\nOfficial references\nMicrosoft Learn: Defender for Endpoint iOS features. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nWith the documented May 2025 iOS app update, Defender open-wireless-network activity moves from alerts to device-timeline events. Repeated connections within a 24-hour period produce only one connection event and one disconnection event. User-trusted open networks are included. The change requires the corresponding app update and does not apply to GCC customers, who retain the previous alert experience. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-endpoint/ios-configure-features).\n\n## Applicability\n\nEstablish the tenant cloud and installed application version before explaining a quiet alert queue or a small event count. Do not assume that a different device’s experience proves which behavior applies to the device under investigation.\n\n## DSE recommendation\n\nInterpret the mobile timeline as the documented summarized event signal, not a complete count of network joins. Ask the security operations owner to update searches and help-desk explanations that still expect a new alert for every connection. If the investigation needs connection frequency, identify an authorized evidence source appropriate to that requirement rather than calculating it from these summarized entries. Keep trusted-network status separate from whether an event can appear.\n\n## Verification\n\nOn a permitted test device, record the app version and cloud, then compare the observed timeline and alert behavior with the applicable documented path. Preserve the time range and device identity when examining repeated activity. State the observation narrowly: an event establishes the reported activity, but the documented one-per-type limit does not support a total reconnection count. Investigate missing expected evidence without inventing unobserved joins.\n\n## Official references\n\n[Microsoft Learn: Defender for Endpoint iOS features](https://learn.microsoft.com/en-us/defender-endpoint/ios-configure-features). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-301-do-not-count-ios-open-network-timeline-entries-as-every-wi-fi-reconnection/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-301-do-not-count-ios-open-network-timeline-entries-as-every-wi-fi-reconnection/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-301-do-not-count-ios-open-network-timeline-entries-as-every-wi-fi-reconnection/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Do not count iOS open-network timeline entries as every Wi-Fi reconnection",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-301-do-not-count-ios-open-network-timeline-entries-as-every-wi-fi-reconnection/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-301-do-not-count-ios-open-network-timeline-entries-as-every-wi-fi-reconnection/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-301-do-not-count-ios-open-network-timeline-entries-as-every-wi-fi-reconnection/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-301-do-not-count-ios-open-network-timeline-entries-as-every-wi-fi-reconnection/",
                "headline": "Do not count iOS open-network timeline entries as every Wi-Fi reconnection",
                "description": "Why can repeated open-Wi-Fi connections produce few Defender timeline events and no new alerts?",
                "abstract": "Why can repeated open-Wi-Fi connections produce few Defender timeline events and no new alerts?",
                "articleBody": "Source facts\nWith the documented May 2025 iOS app update, Defender open-wireless-network activity moves from alerts to device-timeline events. Repeated connections within a 24-hour period produce only one connection event and one disconnection event. User-trusted open networks are included. The change requires the corresponding app update and does not apply to GCC customers, who retain the previous alert experience. Microsoft Learn.\nApplicability\nEstablish the tenant cloud and installed application version before explaining a quiet alert queue or a small event count. Do not assume that a different device’s experience proves which behavior applies to the device under investigation.\nDSE recommendation\nInterpret the mobile timeline as the documented summarized event signal, not a complete count of network joins. Ask the security operations owner to update searches and help-desk explanations that still expect a new alert for every connection. If the investigation needs connection frequency, identify an authorized evidence source appropriate to that requirement rather than calculating it from these summarized entries. Keep trusted-network status separate from whether an event can appear.\nVerification\nOn a permitted test device, record the app version and cloud, then compare the observed timeline and alert behavior with the applicable documented path. Preserve the time range and device identity when examining repeated activity. State the observation narrowly: an event establishes the reported activity, but the documented one-per-type limit does not support a total reconnection count. Investigate missing expected evidence without inventing unobserved joins.\nOfficial references\nMicrosoft Learn: Defender for Endpoint iOS features. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:26:55+00:00",
                "dateModified": "2026-09-10T01:40:02+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-301-do-not-count-ios-open-network-timeline-entries-as-every-wi-fi-reconnection/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-301-do-not-count-ios-open-network-timeline-entries-as-every-wi-fi-reconnection/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Do not count iOS open-network timeline entries as every Wi-Fi reconnection"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Briefing",
                    "Information priority"
                ],
                "genre": "Briefing",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 247,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Configure Microsoft Defender for Endpoint on iOS features - Microsoft Defender for Endpoint | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/defender-endpoint/ios-configure-features"
                }
            }
        ]
    }
}